Repository navigation
ποΈ feat: give each job and deploy its own run token - #306
Open
erick-GeGe wants to merge 3 commits into
Open
erick-GeGe wants to merge 3 commits into
erick-GeGe wants to merge 3 commits into
Conversation
joaquingx
approved these changes
Sep 28, 2026
erick-GeGe
force-pushed
the
feat/oidc-sub
branch
from
September 28, 2026 18:28
9330b9f to
d4ff5f9
Compare
erick-GeGe
force-pushed
the
feat/run-tokens
branch
from
September 28, 2026 18:28
bbcb2d8 to
29c0e09
Compare
erick-GeGe
force-pushed
the
feat/run-tokens
branch
from
September 28, 2026 19:41
29c0e09 to
ed739ad
Compare
A RunToken belongs to one job or one deploy. Only the two endpoints a container reports to accept it, only to update that run, and it stops working once the run is over. Only its hash is stored.
Manual jobs, cron jobs and deploys used to carry a DRF token in JOB_INFO: the launcher's, the project owner's, or deploy_manager's shared one. None of them expire and all can do anything their user can. Each run now gets a token that dies with it. DRF tokens still authenticate, so runs started before this deploy finish normally.
erick-GeGe
force-pushed
the
feat/oidc-sub
branch
from
October 6, 2026 16:16
515e329 to
c292ce2
Compare
erick-GeGe
force-pushed
the
feat/run-tokens
branch
from
October 6, 2026 16:16
ed739ad to
219f0e3
Compare
Not only scheduled ones: a job started by hand goes through the queue too, unless it asks for sync=true. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
To report back, every container estela launches gets a token in
JOB_INFO:?sync=true, which skips the queuedeploy_manager's DRF token, the same one for every deployNone of them ever expire, and all sit in plain text in the pod's environment, readable by anyone who can read the pod. A container needs exactly two endpoints; these tokens open all of them.
What
Each run gets its own token, good only for reporting on itself:
estela-run_β¦token. Only its SHA-256 is stored (RunToken, migration0045_runtoken).PATCH β¦/jobs/{jid}andPUT β¦/deploys/{did}, the only ones containers call. Everywhere else it is not recognised at all, so it cannot create API keys or edit a profile (RUN_AUTHENTICATION_CLASSES).IsOwnRun, opted into per view withrun_token_target).COMPLETED,ERRORorSTOPPED, or the deploySUCCESS,FAILUREorCANCELED, it stops working. No fixed expiry, because jobs have no maximum duration.?sync=truejob as whoever started it (person or API key owner), a deploy asdeploy_manager. Existing permission checks apply unchanged.estela_mistakes one for the other.What does not change
Authorization: Token <value>; only the value is different. No image needs rebuilding.How it was checked
End to end on a local cluster, with the same mechanism on the single sign-on working branch: real spider jobs (manual and queued) and two real deploys reported their status with their own token, and every token was dead once its run finished. That branch differs only in also listing the gateway's JWT class on these two views.
Deploy notes
Migration
0045_runtoken. No configuration change.